Tagged articles

MITRE ATT&CK

9 articles · Page 1 of 1
Black & White Path
Black & White Path
Jul 25, 2026 · Information Security

Deep Dive into wp2shell: A Cross‑Platform RAT Attack Platform

Security researchers monitoring an open directory uncovered the full wp2shell platform, a cross‑platform Go RAT supporting 14 CPU architectures that combines a zero‑credential WordPress exploit chain with large‑scale IoT botnet deployments against Ubiquiti, D‑Link and Totolink devices, featuring fileless execution, post‑quantum TLS, and extensive persistence mechanisms.

IoT botnetMITRE ATT&CKRAT
0 likes · 32 min read
Deep Dive into wp2shell: A Cross‑Platform RAT Attack Platform
Black & White Path
Black & White Path
Jul 10, 2026 · Information Security

JadePuffer: Inside the World’s First Fully Agentic AI Ransomware

JadePuffer, the first ransomware fully driven by a large language model, exploited a CVE‑2025‑3248 flaw in exposed Langflow instances to gain initial access, autonomously performed reconnaissance, credential theft, lateral movement, persistence, and encrypted MySQL/Nacos data, demonstrating rapid self‑healing and highlighting new defensive challenges.

AI ransomwareCloud securityLLM-driven attack
0 likes · 18 min read
JadePuffer: Inside the World’s First Fully Agentic AI Ransomware
Black & White Path
Black & White Path
May 21, 2026 · Information Security

Inside The Gentlemen RaaS Leak: Attack‑Defense Dynamics in Modern Ransomware

The article dissects the May 2026 leak of the ransomware‑as‑a‑service group The Gentlemen, detailing its rapid rise, profit‑sharing model, edge‑device entry points, AI‑assisted tool development, supply‑chain attacks, internal breach, and concrete blue‑team mitigation recommendations.

AI-assisted MalwareBlue teamMITRE ATT&CK
0 likes · 12 min read
Inside The Gentlemen RaaS Leak: Attack‑Defense Dynamics in Modern Ransomware
Black & White Path
Black & White Path
May 15, 2026 · Information Security

Twin Brothers Delete 96 Government Databases – A Privileged‑Account Failure Case Study

In 2025, twin brothers with prior cyber‑crime convictions exploited a privileged‑account gap at a federal‑service contractor, erased 96 government databases within six minutes, used AI to seek log‑clearing methods, and triggered a multi‑layered forensic and legal response that highlights critical gaps in identity‑access management, backup integrity, and insider‑threat detection.

AI-assisted attackMITRE ATT&CKSecurity Monitoring
0 likes · 13 min read
Twin Brothers Delete 96 Government Databases – A Privileged‑Account Failure Case Study
AI Waka
AI Waka
Apr 27, 2026 · Information Security

Building Intelligent Security Agents with Claude Skills: A Complete AI Cybersecurity Guide

The article explains how Anthropic’s Claude Skills framework enables AI agents to execute expert-level cybersecurity tasks by organizing 734+ MITRE ATT&CK‑mapped skills, detailing their structure, progressive loading, real‑world workflows, deployment steps, customization, and the operational benefits for SOCs, detection engineers, and incident responders.

AI securityAgent SkillsClaude
0 likes · 17 min read
Building Intelligent Security Agents with Claude Skills: A Complete AI Cybersecurity Guide
Black & White Path
Black & White Path
Apr 17, 2026 · Information Security

Threat Alert: Cloud‑Native Cybercrime Group TeamPCP Targets Docker, Kubernetes, and Redis

TeamPCP, a newly identified cloud‑native threat group, has compromised at least 60,000 servers worldwide by exploiting exposed Docker APIs, Kubernetes clusters, Redis instances, and the React2Shell vulnerability, employing automated tools such as proxy.sh, kube.py, and react.py, with detailed MITRE ATT&CK mapping and concrete defense recommendations.

Cloud securityDockerKubernetes
0 likes · 16 min read
Threat Alert: Cloud‑Native Cybercrime Group TeamPCP Targets Docker, Kubernetes, and Redis
Black & White Path
Black & White Path
Apr 11, 2026 · Information Security

Inside the Exposed TheGentlemen Ransomware Toolkit on Proton66

In March 2026 Hunt.io researchers uncovered an open directory on the Russian bullet‑proof host Proton66 that contains the full TheGentlemen ransomware toolkit, complete with Mimikatz credential logs, ngrok tokens, and 21 MITRE ATT&CK techniques, providing a detailed view of the attackers' reconnaissance, privilege‑escalation, defense‑evasion, credential‑access, persistence, and encryption‑preparation stages.

Credential DumpingMITRE ATT&CKMimikatz
0 likes · 22 min read
Inside the Exposed TheGentlemen Ransomware Toolkit on Proton66
Black & White Path
Black & White Path
Mar 23, 2026 · Information Security

When Identity Protection Fails: Aura Breaches 900K Records via Vishing Attack

Aura, a provider of identity‑theft protection services, disclosed that a phone‑phishing (vishing) attack in March 2026 exposed roughly 900,000 customer names and email addresses, prompting analysis of the attack vector, MITRE ATT&CK mapping, and lessons on supply‑chain risk and defense‑in‑depth.

AURAMITRE ATT&CKdata breach
0 likes · 7 min read
When Identity Protection Fails: Aura Breaches 900K Records via Vishing Attack